go package report

Is hatchet-dev/hatchet safe?

1 known vulnerability, worst severity MODERATE.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      medium

      severity out of 10

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-fjwv-jf2v-j499, the advisory selected below

      // 1 advisories

      GHSA-fjwv-jf2v-j499

      MODERATECVE-2026-61681
      // summary

      The SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go makes an unvalidated http.Get() call to payload.UnsubscribeURL without any URL restriction. Because UnsubscribeURL is intentionally excluded from the BuildSignature() signed field list, an attacker can replace this field in a legitimately AWS-signed message with an arbitrary internal URL, bypassing the VerifyPayload() signature check entirely and triggering a Server-Side Request Forgery (SSRF) against internal infrastructure — including the EC2 Instance Metadata Service (IMDS) at 169.254.169.254.

      // impact

      This is a Server-Side Request Forgery (SSRF) vulnerability. An attacker with a Hatchet account and an AWS Free Tier account can:

      • Reach the EC2 IMDS endpoint and retrieve IAM temporary credentials if Hatchet is deployed on AWS
      • Port-scan and probe internal services not exposed to the internet
      • Access internal HTTP APIs (e.g., Kubernetes API server, internal dashboards) from the Hatchet server's network

      context

      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      High
      User interaction
      None
      Scope
      Changed
      Confidentiality
      Low
      Integrity
      None
      Availability
      None

      Checked 2026-09-22 at 22:31 UTC. The most recent advisory here was published 2026-09-22. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.
      Is hatchet-dev/hatchet safe? go package security report | CyberXYZ